Senior Security & Compliance Lead – Certifications & GRC

PETADATA

Hyderabad

On-site

INR 450,000 - 700,000

Full time

41 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PETADATA seeks a Senior Security & Compliance Lead to own the certification roadmap, drive SOC 2 and ISO 27001 programs, and mature the ISMS across cloud and on-prem environments. You will coordinate audits, manage evidence, and guide cross‑functional teams to ensure robust security practices and data protection.

The role requires 10+ years in information security and hands-on experience with certifications, cloud security, and risk management.

Qualifications

  • 8+ years in information security, GRC, or security compliance.
  • Hands-on experience leading SOC 2 and/or ISO 27001 certifications end to end.
  • Strong knowledge of SaaS security, multi-tenant environments, cloud security, IAM, encryption, and audit logging.
  • Experience with AWS, GCP, or Azure and cloud shared responsibility.
  • Experience with on-premise/customer-deployed software security and compliance.
  • Strong understanding of risk management, control frameworks, ISMS, audits, and continuous compliance.
  • Knowledge of GDPR, CCPA, and other relevant privacy requirements.
  • Experience with vulnerability management, penetration testing, incident response, and vendor risk management.
  • Strong security documentation and audit evidence management skills.
  • Excellent communication skills with auditors, engineers, customers, and executives.
  • Highly self-directed, with the ability to build and manage a security program independently.
  • Preferred: CISSP, CISA, CISM, CCSP, ISO 27001 Lead Implementer/Auditor, and experience with HIPAA, PCI DSS, NIST, FedRAMP, Vanta, Drata, or DevSecOps.

Responsibilities

  • Own the organization's security certification roadmap, prioritizing certifications and attestations based on business, customer, and market needs.
  • Lead certification programs such as SOC 2 Type I & II, ISO 27001, and related standards including GDPR/privacy, HIPAA, PCI DSS where applicable.
  • Manage end-to-end certification processes: gap assessments, control design, evidence collection, auditor coordination, remediation, and certification.
  • Establish and maintain ISMS with policies, standards, procedures, and supporting docs.
  • Develop a unified control framework mapping controls across standards and deployment models.
  • Build and maintain the security posture for a multi-tenant cloud platform and on-prem environments.
  • Define shared-responsibility models across cloud and customer deployments.
  • Partner with Engineering to embed security controls in the platform and SDLC.
  • Establish vulnerability management, risk assessments, and third-party risk processes.
  • Lead incident response, business continuity, and security awareness initiatives.
  • Manage customer trust programs, audit responses, and documentation portal.
  • Note: Should be able to work independently and work in USA time zones

Skills

Information security
GRC
Security compliance
Cloud security
IAM & encryption
Audit logging
Risk management
ISMS
Vendor risk management
Security documentation
Auditors communication
Independent program ownership

Education

CISSP / CISA / CISM / CCSP certifications
ISO 27001 Lead Implementer/Auditor
Bachelor's degree in CS/IT/Engineering

Tools

Vanta
Drata

Job description

Position: Senior Security & Compliance Lead Certifications & GRC
Location: Hyderabad (8:00 PM -5:00 AM IST)
Work Type: Full-Time
Experience: 10+ Years

PETADATA is looking for a Senior Security & Compliance Lead Certifications & GRC with strong experience in cybersecurity, risk management, compliance frameworks, and enterprise security solutions.

Roles & Responsibilities
Security Certifications & Compliance Program
  • Own the organization's security certification roadmap, determining which certifications and attestations are required and prioritizing them based on business, customer, and market requirements.
  • Lead certification programs such as SOC 2 Type I, SOC 2 Type II, ISO 27001, and, where applicable, ISO 27017/27018, GDPR/privacy, HIPAA, PCI DSS, or CSA STAR.
  • Manage certifications end to end, including gap assessments, control design, control implementation, evidence collection, auditor selection, audit coordination, remediation, and certification.
  • Establish and maintain an Information Security Management System (ISMS), including security policies, standards, procedures, and supporting documentation.
  • Develop a unified control framework that can map controls across multiple security and compliance standards and deployment models.
Cloud & On-Premise Security
  • Build and maintain the compliance posture for a multi-tenant cloud platform, including tenant isolation, data segregation, shared infrastructure controls, and cloud-provider responsibilities.
  • Develop security and compliance requirements for on-premise and customer-deployed environments, including secure deployment, hardening, documentation, and customer audit support.
  • Establish and maintain a clear shared-responsibility model across cloud and customer-managed deployments.
  • Map security controls across cloud environments such as AWS, GCP, and Azure and ensure appropriate security responsibilities are documented and implemented.
Security Engineering & Risk Management
  • Partner with Engineering and Architecture teams to ensure security controls are designed into the platform, rather than added after development.
  • Drive implementation of controls covering encryption, access control, secrets management, logging and auditing, tenant isolation, and secure SDLC practices.
  • Establish and manage vulnerability management, penetration testing, and security review processes, ensuring findings are tracked through remediation and closure.
  • Conduct security risk assessments and manage third-party and vendor security risks.
  • Work closely with technical teams to identify security gaps and develop practical remediation plans.
Security Operations & Business Continuity
  • Establish and maintain incident response, business continuity, and disaster recovery plans, including regular testing and validation.
  • Develop and deliver security awareness training and promote a security-first culture across the organization.
  • Monitor security and compliance controls continuously and coordinate remediation when gaps are identified.
  • Manage ongoing surveillance audits, recertification activities, and compliance monitoring as the organization, platform, and team evolve.
Customer Trust & Audit Management
  • Own the organization's customer security and trust program, responding to security questionnaires, RFP security sections, vendor assessments, and customer audit requests.
  • Maintain security and compliance documentation through a centralized trust/compliance portal.
  • Work directly with customers to explain security controls, compliance posture, shared responsibilities, and deployment-specific requirements.
  • Serve as the primary point of contact for auditors, customers, engineers, and executive stakeholders on security and compliance matters.
  • Translate complex security requirements into clear policies, evidence, documentation, and actionable recommendations.

Note: Should be able to work independently and work in USA time zones

Required Qualifications & Skills
  • 8+ years in information security, GRC, or security compliance.
  • Hands-on experience leading SOC 2 and/or ISO 27001 certifications end to end.
  • Strong knowledge of SaaS security, multi-tenant environments, cloud security, IAM, encryption, and audit logging.
  • Experience with AWS, GCP, or Azure and cloud shared responsibility.
  • Experience with on-premise/customer-deployed software security and compliance.
  • Strong understanding of risk management, control frameworks, ISMS, audits, and continuous compliance.
  • Knowledge of GDPR, CCPA, and other relevant privacy requirements.
  • Experience with vulnerability management, penetration testing, incident response, and vendor risk management.
  • Strong security documentation and audit evidence management skills.
  • Excellent communication skills with auditors, engineers, customers, and executives.
  • Highly self-directed, with the ability to build and manage a security program independently.
  • Preferred: CISSP, CISA, CISM, CCSP, ISO 27001 Lead Implementer/Auditor, and experience with HIPAA, PCI DSS, NIST, FedRAMP, Vanta, Drata, or DevSecOps.
Education

Bachelor s degree in Computer Science, Information Technology, Engineering, or a related field.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security and Compliance Lead
Security and Compliance Lead

Quadrant Technologies • Hyderabad

On-site
INR 2,400,000 - 4,000,000
Senior GRC Analyst
Senior GRC Analyst

3M HEALTHCARE • Hyderabad

On-site
INR 1,500,000 - 2,200,000
GRC Consultant @ Mumbai
GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,800,000 - 2,400,000
Cyber Security GRC Consultant @ Mumbai
Cyber Security GRC Consultant @ Mumbai

Quess IT Solutions • Mumbai

On-site
INR 1,600,000 - 2,800,000
GRC - Security Analyst
GRC - Security Analyst

Jobgether • India

On-site
INR 1,200,000 - 1,800,000
Fully remote in India
Full-time employment
Exposure to multiple security framesk—
+2
Info/Security - Analyst
Info/Security - Analyst

Ascendion Engineering • Hyderabad

On-site
INR 2,500,000 - 3,800,000
Product GRC Consultant
Product GRC Consultant

CyRAACS™ • Bengaluru

On-site
INR 600,000 - 1,200,000
Senior GRC Analyst
Senior GRC Analyst

Exotel Techcom Pvt Ltd • Bengaluru

On-site
INR 800,000 - 1,400,000
GRC Specialist
GRC Specialist

NopalCyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Manager - Information Security
Manager - Information Security

DS Group • Dadri

On-site
INR 2,800,000 - 5,400,000